1. Who we are
Sage Signal Bureau Ltd (company number 16865383) is a private limited company registered in England and Wales. Our registered office is 167–169 Great Portland Street, London, England, W1W 5PF.
In this Privacy Policy, “Sage Signal Bureau”, “Sage”, “we”, “us” and “our” mean Sage Signal Bureau Ltd. We are the controller of personal information collected through our website and, where applicable, through our direct interactions with individuals, except where we act as a processor on behalf of another organisation.
2. What this policy covers
This policy explains what personal information we collect, why we collect it, the lawful bases we rely on, who we may share it with, how long we retain it, how we protect it, and the rights available to individuals.
It applies to visitors to www.sagesignal.co.uk, people who contact us, prospective and existing clients, contractors and workers, representatives of agencies and other business contacts, and people who otherwise interact with us in connection with our services.
3. Personal information we may collect
Depending on your relationship with us, we may collect:
- Identity and contact information, such as name, business name, job title, postal address, email address and telephone number.
- Enquiry and correspondence information, including the contents of messages, emails, calls and other communications.
- Business and engagement information, such as the organisation you represent, service requirements, preferences and information necessary to provide or assess our services.
- Information supplied through website forms, including information you choose to include in free-text fields.
- Technical information, such as IP address, browser type, device information, operating system, approximate location derived from IP address, referring pages and information about how you use our website.
- Cookie and online tracking information, where permitted by law and, where required, with your consent.
- Marketing preferences and records of your interactions with our marketing communications.
- Information necessary to comply with legal, regulatory, fraud-prevention, accounting or record-keeping obligations.
We ask that you do not provide special category data or other sensitive information through general website forms unless it is genuinely necessary and we have provided an appropriate means of collecting it.
4. How we collect information
- Directly from you: For example, when you complete a contact form, request information, make an enquiry or communicate with us.
- From your organisation: Or an agency or other business contact where you are acting in a professional capacity.
- Automatically from your device: When you use our website, subject to applicable cookie and tracking rules.
- From third parties: Such as service providers, professional advisers, public sources or other third parties where lawful and appropriate.
5. Why we use personal information
| Purpose | Typical Lawful Basis |
|---|---|
| Responding to enquiries and communicating with you | Legitimate interests and, where relevant, taking steps at your request before entering into a contract. |
| Providing and administering services | Performance of a contract; legitimate interests; and legal obligations where applicable. |
| Managing client, agency and contractor relationships | Performance of a contract; legitimate interests; and legal obligations where applicable. |
| Billing, accounting, tax, audit and financial administration | Legal obligation and legitimate interests. |
| Protecting our systems, website, people and business | Legitimate interests and, where applicable, legal obligations. |
| Improving our website, services and user experience | Legitimate interests and, where consent is required, consent. |
| Sending direct marketing | Consent where required by PECR; otherwise another lawful basis where legally available and appropriate. |
| Website analytics and non-essential tracking | Consent where required by PECR, with associated UK GDPR processing supported by an appropriate lawful basis. |
| Handling complaints, disputes and legal claims | Legitimate interests and legal obligations. |
| Complying with law or regulatory requirements | Legal obligation. |
6. Lawful bases
We will only process personal information where we have a lawful basis under applicable data protection law. Depending on the circumstances, this may include performance of a contract, taking steps at your request before entering into a contract, compliance with a legal obligation, our legitimate interests, or your consent.
Where we rely on legitimate interests, we consider the relevant purpose, the impact on individuals and whether our interests are appropriately balanced against their rights and expectations.
Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect the lawfulness of processing carried out before withdrawal.
7. Marketing
We may send service-related communications where necessary to administer an existing relationship. We may also send marketing communications where permitted by applicable law. Where consent is required, we will ask for it in a clear manner and will provide a straightforward way to unsubscribe or withdraw consent.
You can opt out of marketing communications at any time by using the unsubscribe mechanism provided or by contacting us.
8. Sharing personal information
We may disclose personal information to trusted third parties where necessary and lawful, including technology and hosting providers, website and analytics providers, communications providers, payroll or professional service providers, accountants, auditors, insurers, legal advisers, regulators, government authorities and other suppliers supporting our business.
Where we use a third party to process personal information on our behalf, we require appropriate contractual and security arrangements. Some third parties may process information as independent controllers rather than as our processors. Where this is the case, their own privacy information may also apply.
We do not sell personal information.
9. International transfers
Where personal information is transferred outside the United Kingdom, we will take steps required by applicable data protection law to ensure an appropriate level of protection. Depending on the destination and circumstances, this may include a UK adequacy regulation, appropriate safeguards such as the International Data Transfer Agreement or UK Addendum, or another lawful transfer mechanism.
10. How long we keep information
We keep personal information only for as long as reasonably necessary for the purposes for which it was collected, including to meet contractual, legal, accounting, regulatory, dispute-resolution and reporting requirements.
Retention periods vary by the type of information and our relationship with you. We periodically review stored information and securely delete or anonymise information when it is no longer required.
11. Security
We maintain appropriate technical and organisational measures designed to protect personal information against accidental or unlawful destruction, loss, alteration, unauthorised disclosure and unauthorised access. Measures may include access controls, authentication, secure systems, staff procedures, supplier controls, backups and security monitoring.
No method of transmission or storage is completely secure. If we become aware of a personal data breach that requires notification under applicable law, we will follow the applicable breach-response and notification requirements.
12. Your data protection rights
Subject to applicable legal conditions and exemptions, you may have the right to:
- Request access to personal information we hold about you;
- Request correction of inaccurate or incomplete information;
- Request erasure in certain circumstances;
- Request restriction of processing in certain circumstances;
- Object to processing based on legitimate interests, including certain direct marketing;
- Receive certain personal information in a structured, commonly used and machine-readable format where the right to data portability applies;
- Withdraw consent where processing is based on consent; and
- Object to solely automated decision-making or profiling where the applicable legal conditions are met.
To exercise a right, contact us using the details in Section 15. We may need to verify your identity before responding. We aim to respond without undue delay and generally within one month.
13. Automated decision-making
We do not currently intend this website to make decisions about individuals based solely on automated processing that produce legal effects or similarly significant effects. If this changes, we will provide the information and safeguards required by applicable law.
14. Children
Our website and services are intended for businesses and adults. We do not knowingly seek to collect personal information from children through the website.
15. Contact us
For privacy or data protection enquiries, requests or complaints, please contact us:
Sage Signal Bureau Ltd
167–169 Great Portland Street
London, England, W1W 5PF
Email: support@sagesignalbureau.co.uk
Telephone: +44 7940 473531
If you remain dissatisfied, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority for data protection.
16. Changes to this policy
We may update this Privacy Policy from time to time to reflect changes in law, regulation, technology, services or our processing activities. The latest version will be published on our website with its effective date.